OceanLotus Hits Vietnam Investors With SPECTRALVIPER in FireAnt Attack
ESET says OceanLotus used a FireAnt Metakit supply chain attack and a separate intrusion to push SPECTRALVIPER onto Vietnamese targets.
Intelligence analysis by GPT-5.4 Mini
ESET ties OceanLotus to two campaigns: one against a Vietnamese construction firm and another that abused FireAnt Metakit updates to infect stock investors. Both point to a more selective focus on domestic espionage and the use of SPECTRALVIPER as the main backdoor.
OceanLotus is like a burglar who sneaks in through a trusted delivery truck instead of breaking the door. In this case, it used a fake software update and hidden tricks to plant spying software on Vietnamese targets.
Analysis
What ESET found
ESET attributes two separate campaigns to OceanLotus, a Vietnam-aligned threat actor active since 2012. One campaign targeted an unnamed Vietnamese infrastructure and transport construction company from late 2024 through February 2026. The other abused FireAnt Metakit, a software platform used by Vietnamese stock investors, to deliver the SPECTRALVIPER backdoor between October 2025 and March 2026.
How the FireAnt attack worked
According to ESET, the attackers used the platform’s normal update path and a lack of signature validation to slip in a malicious setup.exe. After execution, the downloader collected basic host details and sent them to a staging server. From there, the attack used DLL side-loading: a legitimate binary loaded a rogue DLL, which then injected into OneDrive.Sync.Service.exe to launch SPECTRALVIPER.
The backdoor then reached out to a command-and-control server to send encrypted system information. ESET says it has not seen malicious updates through that channel since March 9, 2026, which may mean the campaign ended.
Separate intrusion, same backdoor
The second operation appears to have started with a public-facing Microsoft SQL server, possibly through remote code execution flaws. Once inside, the group kept access for more than a year and used SPECTRALVIPER in multiple variants across compromised hosts. ESET says the malware handled host profiling, lateral movement, and loading more payloads from the attacker’s infrastructure.
Bigger pattern
ESET says the evidence points to a shift in OceanLotus behavior: less emphasis on foreign espionage and more focus on domestic targets. The group has also been linked in the past to surveillance of civil society, media, and dissident targets, but this set of campaigns suggests a renewed concentration on Vietnamese organizations and investors.
Key points
- ESET links OceanLotus to two campaigns using SPECTRALVIPER against Vietnamese targets.
- One attack abused FireAnt Metakit updates to reach a small set of stock investors.
- The update mechanism lacked signature validation, letting a malicious binary run as a legitimate update.
- A separate intrusion may have started from a public Microsoft SQL server and stayed active for over a year.
- ESET says the group appears to be focusing more on domestic espionage than foreign targets.
If the findings lead vendors and users to tighten update signing and checks, it could close off a path the attackers relied on. Public exposure of the tactics may also help defenders spot SPECTRALVIPER activity faster and remove it before more systems are affected.
The campaigns show that attackers can stay hidden for long periods and use trusted software channels to spread malware. If update integrity remains weak or public servers stay exposed, similar intrusions could keep reaching investors and domestic organizations.



